09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Process Monitor (Procmon)<br />

451<br />

ProcDump (continued)<br />

64-bit dump files, 233<br />

thread CPU usage data, 233<br />

thread stack dumps, 422<br />

triggers for dumps, 231–232<br />

viewing dump files, 236–237<br />

process activity<br />

capturing, 104<br />

saving snapshot of, 65<br />

summary of, 134–135<br />

viewing, 39–65, 102. See<br />

also Process Monitor<br />

(Procmon)<br />

Process Activity Summary<br />

dialog box, 134–135<br />

process and diagnostic utilities,<br />

4<br />

Process Disk tab, 63–64<br />

process dump files, 53, 227–237<br />

comments in, 236<br />

commit charges, triggering<br />

with, 232<br />

criteria for, 230–232<br />

DebugView analysis, 242<br />

default thread context, 237<br />

names of, 230<br />

overwriting, 230<br />

path, 229–230, 236<br />

performance counters<br />

triggers, 232<br />

64-bit dumps, 233<br />

unhandled exceptions and,<br />

231<br />

Process Explorer (Procexp), 4, 39<br />

administrative rights for,<br />

42–43, 55, 58<br />

call-stack analysis features,<br />

405–426<br />

command-line options, 98<br />

Configure Symbols dialog<br />

box, 29<br />

CPU usage, 23, 41–42<br />

default configuration settings,<br />

restoring, 98<br />

display options, 95–96<br />

DLL view, 40, 67–77<br />

executable images, full path<br />

of, 432<br />

graphs on toolbar, 65<br />

Handle view, 34, 40, 67–77<br />

image signatures, verifying,<br />

91–92<br />

instances of, 95–96<br />

keyboard shortcuts, 98–99<br />

main window, 40, 43–67<br />

notification area icon, 95<br />

open handles, finding, 384<br />

other user sessions, 97<br />

overview of, 39–43<br />

process activity, saving to text<br />

file, 65<br />

process details, 77–88<br />

process handle table, 74<br />

process list, 40–41, 43–53<br />

processes, creating in, 97<br />

Session column, enabling, 182<br />

shutdown options, 97<br />

status bar, 43, 67<br />

system information, 92–95<br />

vs. Task Manager, 96–97<br />

thread details, 89–91<br />

toolbar, 43, 65–66<br />

updating display, 46<br />

visible window ownership,<br />

displaying, 66–67<br />

x86, x64, and IA64 versions,<br />

40<br />

process handle table, 74<br />

process IDs (PIDs), 21<br />

analyzing processes by, 226<br />

listing processes by, 190<br />

suspending processes by, 206<br />

terminating processes by, 189<br />

Process Image tab, 54–55<br />

Process I/O tab, 61–62<br />

process-killing malware,<br />

429–431<br />

process list, 43–53<br />

color highlighting, 44–45<br />

column configuration, saving,<br />

64–65<br />

columns, customizing display,<br />

53<br />

columns, reordering, 47<br />

columns, resizing, 47<br />

columns, sorting, 47<br />

content, copying, 47<br />

default columns, 46<br />

exited processes, 45<br />

job objects, 51<br />

jobs, 44<br />

logon processes, 49–51<br />

.NET processes, 44<br />

new processes, 45<br />

own processes, 44<br />

packed images, 44<br />

precedence order, 44<br />

process actions, 51–54<br />

Process column, 46, 47<br />

running processes in, 43<br />

services, 44<br />

startup processes, 49–51<br />

suspended processes, 44<br />

system processes, 48<br />

tooltips, 48<br />

tree view, 47<br />

updating display, 46<br />

user processes, 51<br />

Process Memory tab, 57–59<br />

Process menu, 51–53<br />

Process Monitor (Procmon), 4,<br />

101–144<br />

administrative rights for, 102,<br />

126<br />

advanced output, 120<br />

analysis tools, 134–140<br />

Autoscroll feature, 103<br />

backing files, 130–131<br />

boot logging, 127–128, 402–<br />

403, 434<br />

buffer overflow results,<br />

105–107<br />

call-stack analysis features,<br />

405–426<br />

call stack information, 27–28<br />

child processes, searching for,<br />

387<br />

clearing events, 103<br />

column display, customizing,<br />

107–108<br />

column set, default, 104–105<br />

command-line options,<br />

132–134<br />

configuration settings,<br />

importing and exporting,<br />

131<br />

Count Values Occurrences<br />

dialog box, 140<br />

Cross Reference Summary<br />

dialog box, 140<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!